CVE-2025-49812

HIGH7.4EPSS 0.46%

Apache HTTP Server: mod_ssl TLS upgrade attack

發布日:2025/7/10修改日:2025/11/6
也稱為:ALPINE-CVE-2025-49812BIT-apache-2025-49812

描述

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

參考連結(8)